MCP Resources
MCP resources are the data or content an MCP server exposes for a client to read as context.
Prerequisites
Resources vs. Tools
An MCP server exposes two different kinds of things: tools, which perform an action, and resources, which are read-only content a client can pull in as context — a file, a database record, a piece of internal documentation. The distinction matters because reading a resource has no side effects, while calling a tool might.
Performs an action
May have side effects
Invoked with arguments
Read-only content
No side effects
Retrieved directly
How Resources Are Used
- An agent can pull a relevant resource into its context before generating a response, similar in spirit to retrieval in a RAG system — but sourced through an MCP server instead of a vector database.
- Because resources have no side effects, they're generally lower-risk to expose than tools — though the content itself can still be sensitive and needs the same access-control consideration as any other data source.
- A server can expose many resources; a client typically lists what's available and reads specific ones as needed, rather than pulling everything at once.
Warning
Content read from an MCP resource still enters the model's context as external data — the same prompt injection considerations apply as with any other retrieved content.
Common Mistakes
Confusing resources with tools
Resources are read-only content with no side effects; tools perform actions — mixing up the two misrepresents the actual risk profile of each.
Assuming resources are automatically safe because they're read-only
No side effects doesn't mean the content is trustworthy — text read from a resource can still carry injected instructions, the same as any retrieved content.
Not applying access control to resources
A resource can expose sensitive content just as easily as a tool can perform a sensitive action — it deserves the same access-control discipline.
Pulling in every available resource regardless of relevance
Like over-retrieving in RAG, reading unnecessary resources crowds the context window without adding useful information.
Interview Question
What is an MCP resource, and how is it different from an MCP tool?
An MCP resource is read-only content an MCP server exposes — a file, a database record, documentation — that a client can pull in as context, distinct from a tool, which performs an action and may have side effects. An agent typically lists available resources and reads specific ones as needed, similar in spirit to retrieval in a RAG system but sourced through an MCP server. Being read-only makes resources generally lower-risk than tools, but it doesn't make them automatically safe — the content itself can still be sensitive and needs the same access control, and text read from a resource still enters the model's context as external data subject to the same prompt injection considerations as any retrieved content.
What an interviewer may ask next
- Why does the read-only nature of a resource not make it automatically safe to expose?
- How is reading an MCP resource similar to retrieval in a RAG system?
- Why might you apply access control to resources the same way you would to tools?
Explain It in 30 Seconds
An MCP resource is read-only content an MCP server exposes — like a file or database record — that a client can pull in as context, distinct from a tool, which performs an action with possible side effects. Being read-only makes resources generally lower-risk, but not automatically safe: the content can still be sensitive and needs access control, and it still enters the model's context as external data subject to the same prompt injection considerations as any retrieved content.